
Unpatched Citrix NetScaler RCE Zero-Days Exploited in Wild, No IOCs or Fixes Released
Two unpatched RCE zero-days in widely deployed Citrix NetScaler appliances are actively exploited with no fixes or IOCs released. Evidence from forensic work and prior incidents indicates patches will not detect earlier access. Edge infrastructure faces immediate operational risk pending vendor action.
WatchTowr reported the pair of RCE zero-days after monitoring credible rumors, noting both were exploited before any patch existed. The flaws affect edge appliances handling VPN, authentication and load balancing. Citrix has issued no confirmation, workaround or CVSS scoring, and administrators on Reddit have begun powering down units on supplier advice. No evidence or victim names were published.
Prior incidents show the pattern: CVE-2026-19490 was added to CISA KEV in September after an August fix, while a June heap overflow was later shown weaponizable. The Netherlands NCSC 2025 guidance after Dutch zero-day exploitation stressed that patches alone do not clear pre-existing access, recommending snapshot and log analysis. Current Citrix compromise steps require preserving evidence before isolation and credential rotation.
Absence of published IOCs leaves operators unable to confirm prior compromise even after an expected early-October patch. NetScaler 13.1 reached end-of-maintenance on September 15, narrowing supported versions. Management interfaces remain a high-value target when left internet-exposed.
Operators must weigh continued exposure against immediate isolation while awaiting Citrix communications the week of September 28.
Citrix: Security bulletin and patches for both RCE flaws issued by October 3 2026 with CVSS scores above 9.0
Sources (3)
- [1]Primary Source(https://thehackernews.com/2026/09/warning-two-unpatched-citrix-netscaler.html)
- [2]Supporting Source(https://watchtowr.com)
- [3]Supporting Source(https://ncsc.nl)